Defining Port Security - Cisco SGE2000 Reference Manual

Gigabit ethernet switch
Hide thumbs Also See for SGE2000:
Table of Contents

Advertisement

Chapter
4
SGE2000/SGE2000P Gigabit Ethernet Switch Reference Guide
Broadcast Mode — Specifies the Broadcast mode currently enabled on the device. The possible
field values are:
Multicast & Broadcast — Counts Broadcast and Multicast traffic together.
Broadcast Only — Counts only Broadcast traffic.
Broadcast Rate Threshold — The maximum rate (packets per second) at which unknown packets
are forwarded. The rate is 3,500 - 1,000,000 kbits/sec.
3. Modify the relevant fields.
4. Click Apply. Storm control is modified, and the device is updated.

Defining Port Security

Network security can be increased by limiting access on a specific port only to users with specific MAC
addresses. The MAC addresses can be dynamically learned or statically configured. Locked port security
monitors both received and learned packets that are received on specific ports. Access to the locked port
is limited to users with specific MAC addresses. These addresses are either manually defined on the port,
or learned on that port up to the point when it is locked. When a packet is received on a locked port, and
the packet source MAC address is not tied to that port (either it was learned on a different port, or it is
unknown to the system), the protection mechanism is invoked, and can provide various options.
Unauthorized packets arriving at a locked port are either:
Forwarded
Discarded with no trap
Discarded with a trap
Cause the port to be shut down.
Locked port security also enables storing a list of MAC addresses in the configuration file. The MAC
address list can be restored after the device has been reset. Disabled ports are activated from the Port
Security Page.
Note To configure port lock, 802.1x multiple host mode must be enabled.
62
Chapter 4: Configuring Device Security
Defining Traffic Control

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents